Opinion

Security Outsourcing: Creeping Determinism

Security departments that rely too heavily on their outsourcer to troubleshoot problems could be heading for disaster.

By David H. Holtzman

Page 2

"Changes that make the organization more complex may create new ways that it can fail."
-Columbia report

Using contractors is not inherently stupid, but it must be managed and recognized for what it brings to the organization, both good and bad. On the plus side, it is useful to have experts available who are paid only when used. However, security is a management function, not a specialty. The extra complexity that comes with detaching it from the rest of the company should not be taken lightly, any more than a mature organization would consider renting a CFO.

The failure of process is always a tragedy, distinguished in severity and scope by the significance of the mission. Lessons learned in one case apply to all, even if we aren't rocket scientists.

CSO

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors